> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Profile Policy

> Sets the profiles access policy



## OpenAPI

````yaml /services/playfab/api-references/rest/profiles/profiles.openapi.json post /Profile/SetProfilePolicy
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Profiles API
  description: >-
    All PlayFab entities have profiles, which hold top-level properties about
    the entity. These APIs give you the tools needed to manage entity profiles.
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Account Management
    description: Account Management APIs
paths:
  /Profile/SetProfilePolicy:
    post:
      tags:
        - Account Management
      summary: Set Profile Policy
      description: Sets the profiles access policy
      operationId: SetProfilePolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetEntityProfilePolicyRequest'
        description: >-
          This will set the access policy statements on the given entity
          profile. This is not additive, any existing statements will be
          replaced with the statements in this request.
      responses:
        '200':
          $ref: '#/components/responses/SetEntityProfilePolicyResponse'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - EntityToken: []
components:
  schemas:
    SetEntityProfilePolicyRequest:
      description: >-
        This will set the access policy statements on the given entity profile.
        This is not additive, any existing statements will be replaced with the
        statements in this request.
      type: object
      properties:
        CustomTags:
          description: >-
            The optional custom tags associated with the request (e.g. build
            number, external trace identifiers, etc.).
          type: object
        Entity:
          allOf:
            - $ref: '#/components/schemas/EntityKey'
          description: The entity to perform this action on.
        Statements:
          description: The statements to include in the access policy.
          type: array
          items:
            $ref: '#/components/schemas/EntityPermissionStatement'
          x-isclass: true
      required:
        - Statements
        - Entity
      example:
        Statements:
          - Resource: pfrn:data--*!*/Profile/Files/avatar.png
            Action: Read
            Principal:
              FriendOf: 'true'
            Comment: Allow my friends to read my avatar
        Entity:
          Id: '90901000'
          Type: title_player_account
          TypeString: title_player_account
    EntityKey:
      description: >-
        Combined entity type and ID structure which uniquely identifies a single
        entity.
      type: object
      properties:
        Id:
          description: Unique ID of the entity.
          type: string
        Type:
          description: >-
            Entity type. See
            https://learn.microsoft.com/gaming/playfab/features/data/entities/available-built-in-entity-types
          type: string
      required:
        - Id
    EntityPermissionStatement:
      type: object
      properties:
        Action:
          description: >-
            The action this statement effects. May be 'Read', 'Write' or '*' for
            both read and write.
          type: string
        Comment:
          description: >-
            A comment about the statement. Intended solely for bookkeeping and
            debugging.
          type: string
        Condition:
          description: Additional conditions to be applied for entity resources.
          type: object
        Effect:
          allOf:
            - $ref: '#/components/schemas/EffectType'
          description: The effect this statement will have. It may be either Allow or Deny
        Principal:
          description: The principal this statement will effect.
          type: object
        Resource:
          description: >-
            The resource this statements effects. Similar to
            'pfrn:data--title![Title ID]/Profile/*'
          type: string
      required:
        - Resource
        - Action
        - Effect
        - Principal
    SetEntityProfilePolicyResponse:
      type: object
      properties:
        Permissions:
          description: >-
            The permissions that govern access to this entity profile and its
            properties. Only includes permissions set on this profile, not
            global statements from titles and namespaces.
          type: array
          items:
            $ref: '#/components/schemas/EntityPermissionStatement'
          x-isclass: true
      example:
        Permissions:
          - Resource: pfrn:data--title_player_account!90901000/Profile/SomethingCool
            Action: '*'
            Principal:
              ChildOf:
                EntityType: '[SELF]'
            Comment: An example policy
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
    EffectType:
      type: string
      enum:
        - Allow
        - Deny
  responses:
    SetEntityProfilePolicyResponse:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/SetEntityProfilePolicyResponse'
            example:
              code: 200
              status: OK
              data:
                Permissions:
                  - Resource: >-
                      pfrn:data--title_player_account!90901000/Profile/SomethingCool
                    Action: '*'
                    Principal:
                      ChildOf:
                        EntityType: '[SELF]'
                    Comment: An example policy
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    EntityToken:
      type: apiKey
      in: header
      name: X-EntityToken
      description: >-
        This API requires an Entity Session Token, available from the Entity
        GetEntityToken method.

````

## Related topics

- [Set Profile Policy](/services/playfab/api-references/rest/profiles/account-management/set-profile-policy.md)
- [PFProfilesSetProfilePolicyAsync](/services/playfab/api-references/c/pfprofiles/functions/pfprofilessetprofilepolicyasync.md)
- [PFProfilesSetProfilePolicyGetResult](/services/playfab/api-references/c/pfprofiles/functions/pfprofilessetprofilepolicygetresult.md)
- [PFProfilesSetProfilePolicyGetResultSize](/services/playfab/api-references/c/pfprofiles/functions/pfprofilessetprofilepolicygetresultsize.md)
- [Profile Writes Meter API Description](/services/playfab/pricing/meters/profile-writes.md)
